How can I definitely Disable Frontpage extensions?

Kent Brockman

Well-Known Member
PartnerNOC
Jan 20, 2008
1,287
64
178
Buenos Aires, Argentina
cPanel Access Level
Root Administrator
The problem is that cPanel is not detecting whether Frontpage has been compiled and installed and try to use it anyway. Disabling the usage of Frontpage in the Default feature list seems to work, but it is indeed an obscure and not so intuitive way to block it.
I think Frontpage usage should be allowed/permitted from Tweak Settings and that decision must alter the behaviour of showing/hiding FrontPage menu in WHM/cPanel and automatically tick/untick Frontpage usage in default Feature List to prevent that resellers' accounts with no defined packages make accidentally use of Frontpage.

Also, the Uninstall FrontPage Extensions screen should have an option to uninstall these extensions from ALL the domains in the server, in order to allow for a full clearing of Frontpage usage in the whole server. This is not difficult to program, guys ;)
 

Kent Brockman

Well-Known Member
PartnerNOC
Jan 20, 2008
1,287
64
178
Buenos Aires, Argentina
cPanel Access Level
Root Administrator
Why would you create an account without a package? The idea of the packages it to limit / disable certain features, right?
I agree. But I have to mention that we sell reseller packages to webdesign agencies, and designers are not aware of features or packages because they are lazy enough to learn to manage a web hosting node and don't have the staff to manage the technical issues. And I don't think that we are the only server with this problem. Users' lack of knowledge must be mitigated with an intuitive system to reduce the issues that may arise.

That's why this hole in Frontpage management is a hazard when handled by designers. They MUST use FTP to avoid intrusion issues in their nice websites, and the best way is to block completely the access to Frontpage in a thourough and seamless way: if the webadmin don't compile Apache to use Frontpage (and luckily also unticking the proposed Tweak Setting to disable Frontpage), the Frontpage screens should not be shown in WHM interface, for admin nor resellers.


Would you mind laying out the steps to reproduce this and I'll give it a try here to see if I can duplicate the issue.
ok. You must use a server wich actually have been compiled WITH Frontpage.
1) Ensure that your "default" feature list allow to use Frontpage.
2) Recompile Apache WITHOUT Frontpage. This is to "disable" Frontpage in the previous installation.
3) Create a reseller account (Specify which packages can use for account creation: unticked).
4) Login to the WHM panel for this reseller.
5) Create an account without specifying a package.
6) Login via FTP to that new account and you will see the vti_bin folders.

This may or may not compromise the domain or the server, but this is a bug and should be corrected: if you don't allow Frontpage from within Tweak Settings, the Frontpage screens should disappear and the account creation process should not create the Frontpage folders in the public_html folder.

Again, I don't think this is difficult to patch ;)
 

cPanelTristan

Quality Assurance Analyst
Staff member
Oct 2, 2010
7,607
40
248
somewhere over the rainbow
cPanel Access Level
Root Administrator
Hello,

This sounds like a great Feature Request someone might want to open about FrontPage and having it disabled if one doesn't already exist:

Feature Requests for cPanel and WHM

Please feel free to post a link to the feature request or post there in that forum once it has been created.

Thanks!